News

Chinese attackers accessed Canadian government networks – for five years

The Register - Thu, 31/10/2024 - 05:34
India makes it onto list of likely threats for the first time

A report by Canada's Communications Security Establishment (CSE) revealed that state-backed actors have collected valuable information from government networks for five years.…

Categories: News

Windows Themes zero-day bug exposes users to NTLM credential theft

The Register - Wed, 30/10/2024 - 21:30
Plus a free micropatch until Redmond fixes the flaw

There's a Windows Themes spoofing zero-day bug on the loose that allows attackers to steal people's NTLM credentials.…

Categories: News

Fired Disney staffer accused of hacking menu to add profanity, wingdings, removes allergen info

The Register - Wed, 30/10/2024 - 15:12
If you're gonna come at the mouse, you need to be better at hiding your tracks

A disgruntled ex-Disney employee has been arrested and charged with hacking his former employer's systems to alter restaurant menus with potentially deadly consequences. …

Categories: News

Russian spies use remote desktop protocol files in unusual mass phishing drive

The Register - Wed, 30/10/2024 - 12:40
The prolific Midnight Blizzard crew cast a much wider net in search of scrummy intel

Microsoft says a mass phishing campaign by Russia's foreign intelligence services (SVR) is now in its second week, and the spies are using a novel info-gathering technique.…

Categories: News

Beijing claims it's found 'underwater lighthouses' that its foes use for espionage

The Register - Wed, 30/10/2024 - 08:31
Release the Kraken!

China has accused unnamed foreign entities of using devices hidden in the seabed and bobbing on the waves to learn its maritime secrets.…

Categories: News

Uncle Sam outs a Russian accused of developing Redline infostealing malware

The Register - Tue, 29/10/2024 - 23:30
Or: why using the same iCloud account for malware development and gaming is a bad idea

The US government has named and charged a Russian national, Maxim Rudometov, with allegedly developing and administering the notorious Redline infostealer. …

Categories: News

How to jailbreak ChatGPT and trick the AI into writing exploit code using hex encoding

The Register - Tue, 29/10/2024 - 22:30
'It was like watching a robot going rogue' says researcher

OpenAI's language model GPT-4o can be tricked into writing exploit code by encoding the malicious instructions in hexadecimal, which allows an attacker to jump the model's built-in security guardrails and abuse the AI for evil purposes, according to 0Din researcher Marco Figueroa.…

Categories: News

Belgian cops cuff 2 suspected cybercrooks in Redline, Meta infostealer sting

The Register - Tue, 29/10/2024 - 16:35
US also charges an alleged Redline dev, no mention of an arrest

International law enforcement officials have arrested two individuals and charged another in connection with the use and distribution of the Redline and Meta infostealer malware strains.…

Categories: News

The story behind the Health Infrastructure Security and Accountability Act

The Register - Tue, 29/10/2024 - 16:00
Health care breaches lead to legislation

Partner Content  Breaches breed regulation; which hopefully in turn breeds meaningful change.…

Categories: News

Admins better Spring into action over latest critical open source vuln

The Register - Tue, 29/10/2024 - 14:33
Patch up: The Spring framework dominates the Java ecosystem

If you're running an application built using the Spring development framework, now is a good time to check it's fully updated – a new, critical-severity vulnerability has just been disclosed.…

Categories: News

Merde! Macron's bodyguards reveal his location by sharing Strava data

The Register - Tue, 29/10/2024 - 10:32
It's not just the French president, Biden and Putin also reportedly trackable

The French equivalent of the US Secret Service may have been letting their guard down, as an investigation showed they are easily trackable via the fitness app Strava.…

Categories: News

Five Eyes nations tell tech startups to take infosec seriously. Again

The Register - Tue, 29/10/2024 - 08:29
Only took 'em a year to dish up some scary travel advice, and a Secure Innovation … Placemat?

Cyber security agencies from the Five Eyes nations have delivered on a promise to offer tech startups more guidance on how to stay secure.…

Categories: News

Wanted. Top infosec pros willing to defend Britain on shabby salaries

The Register - Tue, 29/10/2024 - 06:26
GCHQ job ads seek top talent with bottom-end pay packets

While the wages paid by governments seldom match those available in the private sector, it appears that the UK's intelligence, security and cyber agency is a long way short of being competitive in its quest for talent.…

Categories: News

JPMorgan Chase sues scammers following viral 'infinite money glitch'

The Register - Mon, 28/10/2024 - 20:45
ATMs paid customers thousands ... and now the bank wants its money back

JPMorgan Chase has begun suing fraudsters who allegedly stole thousands of dollars from the bank's ATMs after a check fraud glitch went viral on social media.…

Categories: News

Feds investigate China's Salt Typhoon amid campaign phone hacks

The Register - Mon, 28/10/2024 - 20:00
'They're taunting us,' investigator says and it looks like it's working

The feds are investigating Chinese government-linked cyberspies breaking into the infrastructure of US telecom companies, as reports suggest Salt Typhoon - the same crew believed to be behind those hacks - has also been targeting phones belonging to people affiliated with US Democratic presidential candidate Kamala Harris, along with Republican candidate Donald Trump and his running mate, JD Vance.…

Categories: News

Brazen crims selling stolen credit cards on Meta's Threads

The Register - Mon, 28/10/2024 - 15:45
The platform 'continues to take action' against illegal posts, we're told

Exclusive  Brazen crooks are selling people's pilfered financial information on Meta's Threads, in some cases posting full credit card details, plus stolen credentials, alongside images of the cards themselves.…

Categories: News

Delta officially launches lawyers at $500M CrowdStrike problem

The Register - Mon, 28/10/2024 - 14:17
Legal action comes months after alleging negligence by Falcon vendor

Delta Air Lines is suing CrowdStrike in a bid to recover the circa $500 million in estimated lost revenue months after the cybersecurity company "caused" an infamous global IT outage.…

Categories: News

Dutch cops pwn the Redline and Meta infostealers, leak 'VIP' aliases

The Register - Mon, 28/10/2024 - 12:01
Legal proceedings underway with more details to follow

Dutch police (Politie) say they've dismantled the servers powering the Redline and Meta infostealers – two key tools in a modern cyber crook's arsenal.…

Categories: News

WordPress forces user conf organizers to share social media credentials, arousing suspicions

The Register - Mon, 28/10/2024 - 06:27
One told to take down posts that said nice things about WP Engine

Organisers of WordCamps, community-organized events for WordPress users, have been ordered to take down some social media posts and share their login credentials for social networks.…

Categories: News

Senator accuses sloppy domain registrars of aiding Russian disinfo campaigns

The Register - Sun, 27/10/2024 - 15:44
Also, Change Healthcare sets a record, cybercrime cop suspect indicted, a new Mallox decryptor, and more

in brief  Senate intelligence committee chair Mark Warner (D-VA) is demanding to know why, in the wake of the bust-up of a massive online Russian disinformation operation, the names of six US-based domain registrars seem to keep popping up as, at best, negligent facilitators of election meddling. …

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News